Hi,
Can anyone tell me if it is possible to change and delete tags by Splunk search? Let me tell you why. I import data from a database. Each time a record is updated, I receive a new event in my index at the same time. Therefore, I am forced to sort all events before I can "dedup". My idea is the following:
When a new event occurs, I give it the tag "latest". When this event receives an update, I want to remove the tag "latest" of the older event and pass it to the new version. Therefore I don't have to sort the data anymore and can use "tag=latest" instead.
I know it isn't the right way to use tags because usually you would tag a field=value expression.
I'm sorry to answer the question myself. But as far as I know, Dedup is set to "sortby - _indextime" by default. Because it always holds the most recent event.
That's why the solution is: | dedup fieldname sortby - _indextime
I'm sorry to answer the question myself. But as far as I know, Dedup is set to "sortby - _indextime" by default. Because it always holds the most recent event.
That's why the solution is: | dedup fieldname sortby - _indextime